CVE-2021-4294
OpenShift OSIN CheckClientSecret timing discrepancy
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the function ClientSecretMatches/CheckClientSecret. The manipulation of the argument secret leads to observable timing discrepancy. The name of the patch is 8612686d6dda34ae9ef6b5a974e4b7accb4fea29. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216987.
Se encontró una vulnerabilidad en OpenShift OSIN. Ha sido clasificada como problemática. Esto afecta a la función ClientSecretMatches/CheckClientSecret. La manipulación del secreto argumental conduce a una discrepancia temporal observable. El nombre del parche es 8612686d6dda34ae9ef6b5a974e4b7accb4fea29. Se recomienda aplicar un parche para solucionar este problema. El identificador asociado de esta vulnerabilidad es VDB-216987.
Es wurde eine Schwachstelle in OpenShift OSIN ausgemacht. Sie wurde als problematisch eingestuft. Es geht dabei um die Funktion ClientSecretMatches/CheckClientSecret. Dank Manipulation des Arguments secret mit unbekannten Daten kann eine observable timing discrepancy-Schwachstelle ausgenutzt werden. Der Patch wird als 8612686d6dda34ae9ef6b5a974e4b7accb4fea29 bezeichnet. Als bestmögliche Massnahme wird Patching empfohlen.
A vulnerability was found in OpenShift OSIN. This issue affects the ClientSecretMatches/CheckClientSecret function, where the manipulation of the argument secret leads to an observable timing discrepancy.
Red Hat OpenShift Container Platform release 4.13.41 is now available with updates to packages and images that fix several bugs and add enhancements. Issues addressed include denial of service and traversal vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-12-28 CVE Reserved
- 2022-12-28 CVE Published
- 2024-08-03 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-203: Observable Discrepancy
- CWE-208: Observable Timing Discrepancy
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://github.com/openshift/osin/pull/200 | Issue Tracking |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/openshift/osin/commit/8612686d6dda34ae9ef6b5a974e4b7accb4fea29 | 2024-05-17 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2021-4294 | 2024-05-16 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2156871 | 2024-05-16 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Openshift Container Platform Search vendor "Redhat" for product "Openshift Container Platform" | 4.0 Search vendor "Redhat" for product "Openshift Container Platform" and version "4.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Openshift Osin Search vendor "Redhat" for product "Openshift Osin" | 1.0.0 Search vendor "Redhat" for product "Openshift Osin" and version "1.0.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Openshift Osin Search vendor "Redhat" for product "Openshift Osin" | 1.0.1 Search vendor "Redhat" for product "Openshift Osin" and version "1.0.1" | - |
Affected
|